Back to skill

Security audit

seedance2.0开源版

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent AI video-generation skill, but it needs review because its script can expose the API key during video downloads and its credential guidance is weak.

Install only if you are comfortable sending video prompts and parameters to redfox.hk/upstream video providers. Prefer REDFOX_API_KEY in your environment over --api-key or plaintext config files, avoid sensitive or regulated content in prompts, and review/fix the download-session and filename-prefix issues before using this in a higher-trust environment.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/videogen.py:190
Finding

API Key Disclosure Through Untrusted Video Download URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/videogen.py:190
Finding

Path Traversal Through the User-Controlled Output Filename Prefix

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:167
Finding

API Key Exposure Through Command-Line Arguments and Insecure Configuration Guidance

Content
View full analysis
~/.qoder/apis/redfox.json` | ``` The implementation accepts command-line credentials and reads a plaintext file: ```python def get_api_key(cli_key=None): """Get API key: CLI arg > env var > config file.""" if cli_key: return cli_key env_key = os.environ.get(ENV_KEY) if env_key: return env_key if CONFIG_FILE.exists(): try: data = json.loads(CONFIG_FILE.read_text()) key = data.get("api_key") if key: return key except (json.JSONDecodeError, OSError): pass return None ``` ```python parser.add_argument("--api-key", help="API Key (前往 https://redfox.hk/settings/api-keys?source=clawhub 注册获取)") ``` ### Technical Analysis Passing a secret through `--api-key` places it in the process argument vector. Depending on the operating system and local security configuration, command-line arguments may be visible to other local users, process-monitoring software, crash reports, terminal logging, or administrative tools. The command is also likely to remain in shell history. The documented configuration-file command stores the key as plaintext without explicitly setting restrictive permissions. The resulting file mode depends ...[truncated 1577 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README’s invocation guidance is broad and trigger-oriented around generic user intents like '生成…视频' and '查询任务…结果', without clear boundaries for when this skill should or should not be selected. In an agentic environment, that can cause over-invocation on loosely related prompts, leading to unintended external API calls, unnecessary spend, and possible transmission of user-provided sensitive text to a third-party video service.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares no explicit tool scope even though its documentation clearly indicates access to environment variables, local file reads, and outbound network calls. Without a declared permission boundary, an agent platform may invoke the skill with broader capabilities than users expect, increasing the chance of unintended secret access or data egress.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation text uses broad trigger terms like 'AI 视频' and 'text-to-video', which can cause the skill to be selected for loosely related user requests. Overbroad routing increases the risk that prompts or files are sent to this third-party workflow when the user did not intend to use it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Although the document mentions redfox.hk and the underlying model provider, it does not give a clear privacy warning that user prompts and generated media are transmitted to third-party services. Users may disclose sensitive prompts or business content without informed consent, leading to unintended external data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation recommends passing API keys on the command line and storing them in a plaintext JSON file, but does not warn that command-line arguments can end up in shell history and process listings and that plaintext files may be readable by other local users or backups. This increases the chance of credential leakage and later unauthorized API use.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill explicitly instructs users to persist the API key in a plaintext file under ~/.qoder/apis/redfox.json for reuse across sessions. Persistent plaintext secret storage expands the exposure window: other local processes, users, backup systems, or malware can recover the credential long after initial setup.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
|----------|------|------|
| **环境变量**(推荐) | 设置一次,全局生效 | `export REDFOX_API_KEY=ak_你的密钥` |
| **命令行参数** | 临时使用,单次生效 | `python3 "$SKILL_PATH/scripts/videogen.py" "prompt" --api-key ak_你的密钥` |
| **配置文件** | 持久化存储,跨会话保留 | `mkdir -p ~/.qoder/apis && echo '{"api_key":"ak_你的密钥"}' > ~/.qoder/apis/redfox.json` |

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings and usage text in Chinese, including the module description and command examples, while not offering any language-selection mechanism. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The confirmation prompt and many user-facing CLI messages are emitted only in Chinese, which constrains interaction to a single language without opt-in. Because the file does not offer a locale choice or document a justified region-specific restriction, this conflicts with the language policy requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.